TicTac Learn DPA
This Data Processing Agreement ("DPA") forms part of the agreement between the TicTac entity identified as the contracting party in the Agreement ("TicTac") and the Customer (the "Agreement") and applies strictly and exclusively to the extent that TicTac processes Personal Data on behalf of the Customer in connection with the specific products and services governed by the Agreement (e.g., Trainings, TicTac products, AI content production services, TicTac Support, Docebo support services, Articulate support services, and Vyond support services).
For the avoidance of doubt, the processing of personal data within third-party platforms resold or provided by TicTac (such as the Docebo, Skillhabit, Vyond, or Articulate 360 platforms) is governed by their respective separate data processing agreements. This DPA covers TicTac's own processing in connection with the services listed in Annex 1, including support services related to such platforms.
This DPA is incorporated by reference in the Agreement between TicTac and the Customer, whether through TicTac's Terms of Purchase (available at https://www.tictaclearn.net/terms-of-purchase), a separate service agreement, or an order form. In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.
1. Definitions
Terms defined in the GDPR and in the Agreement have the same meaning in this DPA. In addition:
(a) "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).
(b) "Personal Data" means any personal data (as defined in Article 4(1) of the GDPR) processed by TicTac on behalf of the Customer under the Agreement.
(c) "Data Breach" means a personal data breach as defined in Article 4(12) of the GDPR.
(d) "Sub-processor" means any third party engaged by TicTac to process Personal Data on behalf of the Customer.
(e) "Processing Instructions" means the Customer's documented instructions for TicTac's processing of Personal Data, as set out in Annex 1 and in the applicable order.
2. Scope and roles
The Customer is the controller and TicTac is the processor of the Personal Data processed under this DPA.
The subject matter, nature, purpose, duration, types of Personal Data, and categories of data subjects are described in Annex 1.
This DPA applies to all processing of Personal Data that TicTac carries out on behalf of the Customer in the performance of the Agreement, including (without limitation) processing of Personal Data contained in customer materials, course participant data, and any other Personal Data that the Customer submits to TicTac in connection with an order.
3. Processing instructions
TicTac shall process Personal Data only on the Customer's documented instructions, unless required to do so by EU or Member State law to which TicTac is subject, in which case TicTac shall (to the extent permitted by law) inform the Customer of that legal requirement before processing.
The Terms of Purchase, the applicable order, service agreement and this DPA (including Annex 1) constitute the Customer's complete instructions for TicTac's processing of Personal Data at the time of entering into the Agreement. The Customer may issue additional reasonable instructions that are consistent with the Agreement, provided that such instructions are given in writing.
TicTac shall immediately inform the Customer if, in TicTac's opinion, an instruction from the Customer infringes the GDPR or other applicable data protection law.
4. Confidentiality
TicTac shall ensure that any person authorized to process Personal Data under this DPA is bound by appropriate confidentiality obligations, whether by contract or by statutory obligation.
5. Security measures
TicTac shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of data subjects.
6. Sub-processors
The Customer grants TicTac general written authorization to engage Sub-processors for the processing of Personal Data under this DPA.
TicTac maintains a current list of Sub-processors at https://www.tictaclearn.net/trust-center (the "Sub-processor List"). TicTac shall update the Sub-processor List at least thirty (30) days before engaging a new Sub-processor or replacing an existing Sub-processor. The Customer may subscribe to notifications of updates to the Sub-processor List via the mechanism specified on that page.
If the Customer has a legitimate, data-protection-related objection to the engagement of a new Sub-processor, the Customer shall notify TicTac in writing within fourteen (14) days of the update to the Sub-processor List.
The parties shall discuss the objection in good faith to find a commercially reasonable alternative. If the parties are unable to resolve the objection, the Customer's sole remedy is to terminate the uncompleted portion of the affected order by written notice. In such event, the Customer shall not be entitled to a full refund, but remains obligated to pay for all services performed and deliverables produced by TicTac up to the date of termination, notwithstanding any general "no cancellation" policies in the Agreement.
If the Customer does not object in writing within the fourteen (14) day period, the Customer is deemed to have accepted the new Sub-processor.
TicTac shall impose data protection obligations on each Sub-processor that are no less protective than those set out in this DPA. TicTac remains fully liable to the Customer for the performance of each Sub-processor's obligations.
7. Data subject rights
TicTac shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (including rights of access, rectification, erasure, restriction, portability, and objection).
If TicTac receives a request directly from a data subject, TicTac shall promptly forward the request to the Customer and shall not respond to the data subject directly unless instructed to do so by the Customer or required by law.
To the extent that TicTac's assistance requires significant effort beyond what is reasonable, TicTac may charge the Customer a reasonable fee based on TicTac's actual costs.
8. Data breach notification
TicTac shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Data Breach affecting Personal Data processed under this DPA.
The notification shall include, to the extent available:
(a) a description of the nature of the Data Breach, including the categories and approximate number of data subjects and Personal Data records affected;
(b) the name and contact details of a contact person at TicTac from whom further information can be obtained;
(c) a description of the likely consequences of the Data Breach; and
(d) a description of the measures taken or proposed to be taken to address the Data Breach and to mitigate its possible adverse effects.
If it is not possible to provide all information at the time of notification, TicTac shall provide the information in phases without further undue delay.
TicTac shall cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of the Data Breach.
9. Assistance with compliance
TicTac shall, taking into account the nature of the processing and the information available to TicTac, assist the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 of the GDPR (security of processing, data protection impact assessments, and prior consultation with supervisory authorities).
10. Audit
TicTac shall make available to the Customer all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
Audits shall be conducted as follows:
(a) The Customer shall give TicTac at least thirty (30) days' prior written notice of any audit.
(b) Audits shall be conducted during normal business hours and shall not unreasonably disrupt TicTac's operations.
(c) TicTac shall bear its own costs in connection with completing questionnaires provided by the Customer as part of the Customer's ongoing supervision. For on-site audits or inspections, the Customer shall bear its own costs. If an on-site audit requires significant involvement from TicTac's personnel beyond providing standard documentation, TicTac may charge a reasonable fee.
(d) Audit results and any information obtained during an audit shall be treated as Confidential Information under the Agreement.
Where TicTac has obtained a relevant third-party certification or audit report (such as SOC 2 or ISO 27001), TicTac may offer such certification or report as an alternative to an on-site audit, provided that the Customer may still request an on-site audit if the certification or report does not adequately address the Customer's concerns.
11. International transfers
TicTac shall not transfer Personal Data to a country outside the European Economic Area ("EEA") unless an adequate level of protection is ensured by one of the following mechanisms:
(a) the European Commission has issued an adequacy decision for the recipient country (Article 45 GDPR);
(b) appropriate safeguards have been provided, such as standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR); or
(c) a derogation under Article 49 GDPR applies.
Where a Sub-processor is located outside the EEA, the applicable transfer mechanism is specified in Annex 2.
12. Duration, return and deletion
This DPA shall remain in effect for as long as TicTac processes Personal Data on behalf of the Customer under the Agreement.
Upon completion of the services relating to a specific order, or upon earlier termination of the order, TicTac shall, at the Customer's choice, delete or return all Personal Data processed in connection with that order within thirty (30) days, unless EU or Member State law requires further storage of the Personal Data. The Customer shall communicate its choice in writing. If the Customer does not communicate a choice within fifteen (15) days after completion or termination, TicTac shall delete the Personal Data.
TicTac shall provide written confirmation of deletion upon the Customer's request.
13. Liability
The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
Nothing in this DPA limits or excludes either party's liability to data subjects or to supervisory authorities under applicable data protection law, to the extent that such limitation or exclusion is not permitted by law.
Annex 1: Description of processing
A. Trainings
Data subjects: Course participants, customer contact persons.
Categories of personal data: Name, email address, company/organization, phone number, job title, attendance records, course completion data.
Purpose of processing: Training delivery, administration, attendance tracking, and certification.
Duration of processing: From registration until 30 days after the training has been completed, unless a longer period is required for certification records.
Special categories of data: None expected. The Customer shall not provide special category data without prior written agreement.
B. TicTac products
Data subjects: Customer contact persons, individuals whose personal data is included in customer materials (e.g., names or images in brand guidelines).
Categories of personal data: Name, email address, company/organization, and any personal data contained in customer materials (which may include names, images, and job titles).
Purpose of processing: Production and delivery of the ordered TicTac product.
Duration of processing: From receipt of customer materials until 30 days after delivery of the finished product.
Special categories of data: None expected. The Customer shall not provide special category data without prior written agreement.
C. AI content production services
Data subjects: Customer contact persons, individuals whose personal data is included in source material provided by the Customer (e.g., names, roles, contact details, or images).
Categories of personal data: Name, email address, company/organization, and any personal data contained in source material (which may include names, job titles, images, contact details, and other information chosen by the Customer).
Purpose of processing: AI-assisted course production, expert validation, branding, and delivery; localization where ordered.
Duration of processing: From receipt of source material (or order confirmation if no source material) until 30 days after delivery of the finished course (or localized versions, if applicable).
Special categories of data: None expected. The Customer shall not include special category data (Article 9 GDPR) in source material without prior written agreement with TicTac.
D. TicTac Support
Data subjects: Licensed users, customer contact persons and administrators.
Categories of personal data: Name, email address, company/organization, support ticket content, course completion data and any personal data contained in e-learning projects submitted for audit.
Purpose of processing: Provision of TicTac Support services: prioritized support handling, user access provisioning, live support sessions, and e-learning project audit.
Duration of processing: From activation of TicTac Support until 30 days after termination or opt-out of TicTac Support.
Special categories of data: None expected. The Customer shall not include special category data in support requests or project audit submissions without prior written agreement.
E. Docebo support services
Data subjects: Licensed Docebo users, customer administrators, customer contact persons.
Categories of personal data: Name, email address, company/organization, support ticket content (which may include screenshots, error logs, user IDs, and platform URLs containing user-identifiable information).
Purpose of processing: Provision of Tier 1 and Tier 2 support services: receiving and handling support requests, troubleshooting, and escalating Tier 3 issues to Docebo.
Duration of processing: From creation of support ticket until 30 days after ticket closure, unless a longer period is required for audit or compliance purposes.
Special categories of data: None expected. The Customer shall not include special category data in support requests without prior written agreement.
F. Articulate support services
Data subjects: Licensed Articulate users, customer administrators, customer contact persons.
Categories of personal data: Name, email address, company/organization, support ticket content (which may include screenshots, error logs, user IDs, and platform URLs containing user-identifiable information).
Purpose of processing: Provision of first-level support services: receiving and handling support requests, troubleshooting, and escalating issues to Articulate.
Duration of processing: From creation of support ticket until 30 days after ticket closure, unless a longer period is required for audit or compliance purposes.
Special categories of data: None expected. The Customer shall not include special category data in support requests without prior written agreement.
G. Vyond support services
Data subjects: Licensed Vyond users, customer administrators, customer contact persons.
Categories of personal data: Name, email address, company/organization, support ticket content (which may include screenshots, error logs, user IDs, and platform URLs containing user-identifiable information).
Purpose of processing: Provision of first-level support services: receiving and handling support requests, troubleshooting, and escalating issues to Vyond.
Duration of processing: From creation of support ticket until 30 days after ticket closure, unless a longer period is required for audit or compliance purposes.
Special categories of data: None expected. The Customer shall not include special category data in support requests without prior written agreement.
Annex 2: Sub-processors
Microsoft Corporation
Applies to: All services.
Purpose: Cloud infrastructure and productivity platform (Microsoft 365: email, document storage, video conferencing, collaboration tools) used in the delivery of TicTac services.
Location: USA (EU Data Boundary: customer data stored and processed in EU/EFTA for M365 tenants provisioned in the EU).
Transfer mechanism: EU-US Data Privacy Framework.
Zendesk, Inc.
Applies to: Support services (TicTac Support, Docebo Support Services, Articulate Support Services and Vyond Support Services).
Purpose: Customer support platform (ticket management, user tagging, help centre) for TicTac support services.
Location: USA (EU data hosting available via AWS Ireland/Frankfurt).
Transfer mechanism: EU-US Data Privacy Framework.
Docebo S.p.A.
Applies to: Docebo Support Services only.
Purpose: Tier 3 support escalation: receipt and processing of support ticket data escalated by TicTac, including user-identifiable information contained in support tickets.
Location: EU with support access from USA, UK and Canada.
Transfer mechanism: –